Vulnerabilidades em Ivanti

391 resultados
Análise Vexday

Com 24 vulnerabilidades confirmadas em exploração ativa dentro de um universo de 366 CVEs catalogadas, a taxa de presença no catálogo KEV da CISA é 14,6 vezes acima da média geral do catálogo, o que indica um histórico consistente de interesse de agentes de ameaça nos produtos Ivanti. Das 366 falhas, 83 são classificadas como críticas e 20 possuem prova de conceito pública disponível, aumentando a superfície de risco para organizações que não mantêm ciclos de correção agressivos. O tipo de falha mais recorrente é CWE-89 (injeção de SQL), sugerindo lacunas estruturais em validação de entradas que tendem a produzir vulnerabilidades de alto impacto. A CVE mais perigosa atualmente ativa, CVE-2024-21893, registra EPSS máximo de 1,0, indicando probabilidade extremamente elevada de exploração, e deve ser tratada como prioridade absoluta de remediação.

CVE-2022-36972CRITICALThis vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific fEPSS 6.5%CVE-2022-36979HIGHThis vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although autheEPSS 6.5%CVE-2022-36976CRITICALThis vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific fEPSS 6.5%CVE-2022-36975CRITICALThis vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific fEPSS 6.5%CVE-2024-50322HIGHPath traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthentEPSS 6.0%CVE-2022-36973CRITICALThis vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although autheEPSS 6.0%CVE-2024-11639CRITICALAn authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrativeEPSS 4.9%CVE-2022-36983HIGHThis vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not reqEPSS 4.7%CVE-2025-22467CRITICALA stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote codeEPSS 4.7%CVE-2024-29204CRITICALA Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to eEPSS 4.3%CVE-2023-46803HIGHAn attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial ofEPSS 4.1%CVE-2023-46804HIGHAn attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial ofEPSS 4.1%CVE-2023-46265MEDIUMAn unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).EPSS 4.0%CVE-2024-22052HIGHA null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenEPSS 3.8%CVE-2024-10811CRITICALAbsolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteEPSS 3.6%CVE-2024-22061HIGHA Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to exEPSS 3.6%CVE-2024-22053HIGHA heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malEPSS 3.5%CVE-2024-13158HIGHAn unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allowEPSS 3.5%CVE-2023-46266HIGHAn attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.EPSS 3.5%CVE-2024-32839HIGHSQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticEPSS 3.4%